Advertisement






Tiki Wiki CMS Groupware 25.0 Cross Site Request Forgery

CVE Category Price Severity
CVE-2023-22852 CWE-352 $500 High
Author Risk Exploitation Type Date
Unknown Critical Remote 2023-01-11
CPE
cpe:cpe:/a:tikiwiki:tiki_wiki_cms_groupware:25.0
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2023010014

Below is a copy:

Tiki Wiki CMS Groupware 25.0 Cross Site Request Forgery
------------------------------------------------------------------------------
Tiki Wiki CMS Groupware <= 25.0 Two Cross-Site Request Forgery 
Vulnerabilities
------------------------------------------------------------------------------


[-] Software Link:

https://tiki.org


[-] Affected Versions:

Version 25.0 and prior versions.


[-] Vulnerabilities Description:

1) The /tiki-importer.php script does not implement any protection 
against Cross-Site Request Forgery (CSRF) attacks. As such, an attacker 
might force an authenticated user to import arbitrary content (wiki 
pages) into TikiWiki by tricking a victim user into browsing to a 
specially crafted web page.

2) The /tiki-import_sheet.php script does not implement any protection 
against Cross-Site Request Forgery (CSRF) attacks. As such, an attacker 
might force an authenticated user to import arbitrary sheets into 
TikiWiki by tricking a victim user into browsing to a specially crafted 
web page. Successful exploitation of this vulnerability requires the 
Spreadsheets feature to be enabled.


[-] Solution:

No official solution is currently available.


[-] Disclosure Timeline:

[06/03/2022] - Vendor notified
[09/01/2023] - Public disclosure


[-] CVE Reference:

The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CVE-2023-22852 to this vulnerability.


[-] Credits:

Vulnerabilities discovered by Egidio Romano.


[-] Original Advisory:

http://karmainsecurity.com/KIS-2023-01


Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum